Methodology
What the desk reads, how it decides what matters, and what its guidance is and is not.
Where the newsdesk material comes from
Every article on the newsdesk is written from public regulatory and compliance reporting. Eight feeds are polled continuously:
- SEC press releases — enforcement actions, settlements and rulemaking, taken from the primary source rather than coverage of it.
- FTC press releases — consumer protection and data security enforcement.
- ICO (UK) — UK data protection enforcement, monetary penalties and published guidance.
- European Data Protection Board — EDPB opinions, guidelines and coordinated enforcement across the EU.
- Four rolling news searches covering audit and internal controls, GDPR and privacy enforcement, the certification frameworks (SOC 2, PCI DSS, ISO 27001, HIPAA, NIST), and PCAOB and audit quality.
Nothing is republished. Each item is a pointer to somebody else's reporting or to a regulator's own announcement, and the desk's job is the layer on top: what it means for a compliance function, which frameworks it touches, and what to do about it. Every article lists the specific items it was written from, with links, so any claim can be traced back.
How stories are selected
Far more crosses the wire than is worth writing about. Items are assessed before anything is written, on:
- Materiality — how much this should change what a compliance officer does, on a five-point scale. A first-of-its-kind enforcement action outranks a routine settlement at the same value.
- Frameworks touched — which of SOC 2, ISO 27001, PCI DSS, HIPAA, NIST, GDPR or SOX the item actually bears on. Items that touch nothing concrete are dropped.
- Regulator — who is acting, and whether their remit reaches the readership.
- Novelty — whether the desk has already covered this, and whether the story has moved since.
Framework and control guidance
The framework hub is a different thing from the newsdesk and should be read differently. Every control reference and title is taken from the standard itself and is accurate. The explanatory guidance around each one — what it means in practice, what auditors typically ask for, common ways organisations fail it — is the site's own commentary, written to be useful to somebody preparing for an audit.
The scope is deliberately a defensible starting set rather than a complete reproduction of any standard. Standards bodies license their full texts; this site does not reproduce them, and it is not a substitute for the standard, for your auditor, or for professional advice. Where a control's wording matters, read the source.
Crosswalks
Framework crosswalks map controls that address the same underlying risk across different standards. They are an aid to scoping, not an equivalence claim: two controls can cover the same ground and still differ in evidence requirements, testing frequency and scope. A crosswalk tells you where to look first; your auditor decides what satisfies them.
Corrections
The desk gets things wrong. When it does, the page is corrected rather than quietly edited. If something here is inaccurate — a control reference, a description of an enforcement action, or a claim about your organisation — write to contact@auditen.com and it will be fixed. Named organisations are offered a right of reply.
Limits
This is a reading of public material, produced quickly and at volume. It is not legal advice, not an audit opinion, and not a substitute for a qualified practitioner who knows your environment. The wire is checked, but it is not primary research: if a source got it wrong, this site can repeat the error. Verify before you act, and follow the links.